Prisma Access
Your Prisma Access License
Table of Contents
Expand All
|
Collapse All
Prisma Access Docs
-
- Prisma Access China
- 4.0 & Later
- 3.2 Preferred and Innovation
- 3.1 Preferred and Innovation
- 3.0 Preferred and Innovation
- 2.2 Preferred
-
-
-
- 5.2 Preferred and Innovation
- 5.1 Preferred and Innovation
- 5.0 Preferred and Innovation
- 4.2 Preferred
- 4.1 Preferred
- 4.0 Preferred
- 3.2 Preferred and Innovation
- 3.1 Preferred and Innovation
- 3.0 Preferred and Innovation
- 2.2 Preferred
Your Prisma Access License
Prisma Access
LicenseLearn about
Prisma Access
licenses.Where Can I Use This? | What Do I Need? |
---|---|
|
|
Prisma Access
offers a licensing model that allows you to implement and use the
capabilities of Prisma Access
aligned to your business needs in a way that delivers the
fastest return on investment. Whether your applications are migrating to the cloud, your
users are working from anywhere, or if you are looking to gain operational efficiencies,
Prisma Access
offers the relevant type of license for your deployment. You can choose from the following license editions (more details are in the
Prisma Access
):- Business
- Business Premium
- Zero Trust Network Access (ZTNA) Secure Internet Gateway (SIG)
- Enterprise
Your
Prisma Access
license edition determines the security capabilities that are
available to you. If you use any capability in security rules or profiles that is
unsupported based on your license type, Prisma Access
removes those configurations
and those capabilities are not enforced in your Prisma Access
tenants until you
update Prisma Access
with a license edition that supports those capabilities. To
find the capabilities included with your license, refer to the Prisma Access
. All license editions are available for Local and Worldwide
Prisma Access
locations. When
you purchase a license with Worldwide locations, you can deploy Prisma Access
in all
Prisma Access
locations. When you purchase a license with Local locations, you can
select up to five Prisma Access
locations.Prisma Access
uses units
in licenses, and uses the following definitions for a
unit: - For mobile user deployments, aunitis defined as one mobile user. When you assign units inPrisma Accessfrom your Mobile users license, each unit allows a mobile user to utilizePrisma Access—GlobalProtect, Prisma Access—Explicit Proxy, or both GlobalProtect and Explicit Proxy.
- For remote network and Clean Pipe deployments, aunitis defined as 1 Mbps of bandwidth.
When a
Prisma Access
license expires, you can still use the service and collect logs
for 15 days after license expiration. You cannot make changes to configuration.
Prisma Access
shuts down its instances 15 days after license expiration and
completely deletes the instances and tenants 30 days after license expiration.License Enforcement for Prisma Access Mobile User Deployments
Prisma Access
Mobile User DeploymentsLearn how mobile user (GlobalProtect) licenses are counted in Prisma
Access.
Prisma Access
uses these enforcement policies for mobile user licenses:- Though there is no strict policing of the mobile user count, the service does track the number of unique users over the last 30 days to ensure that you have purchased the proper license tier for your user base, and stricter policing of user count may be enforced if continued overages occur.
- APrisma AccessMobile User license allows you to use both GlobalProtect and explicit proxy connect methods. With a single Mobile User license, the user can connect with GlobalProtect, Explicit Proxy, or both.
- If you usePrisma Accessfor users—GlobalProtect, the GlobalProtect app is required on each supported endpoint. The GlobalProtect app is not required for Mobile Users—Explicit Proxy deployments.
Other Required Prisma Access Licenses (Panorama)
Prisma Access
Licenses (Panorama)See the other licenses that are required for
Prisma Access
.In addition to the
Prisma Access
licenses, in order to run the service you must also
have the following licensed components:- Panorama—You deploy and managePrisma Accessusing the Cloud Services plugin for Panorama. In order to use this plugin, you must have Panorama with a valid support license. See the Palo Alto Networks Compatibility Matrix for the Panorama versions that are supported with the Cloud Services plugin. When you license thePrisma Accesscomponents, you must tie the auth code to a licensed Panorama serial number.
- —TheStrata Logging ServicePrisma Accessinfrastructure forwards all logs to Strata Logging Service. You can view thePrisma Accesslogs, ACC, and reports directly from Panorama for an aggregated view into your remote network and mobile user traffic. To enable logging forPrisma Access, you must purchase aStrata Logging Servicelicense.
Other Licenses to Use With Prisma Access (Managed by Strata Cloud Manager)
Prisma Access (Managed by Strata Cloud Manager)
Cloud services that you want to integrate with
Prisma Access
must be
deployed in the same region as Prisma Access
. You can integrate these cloud services
with Prisma Access
when you first activate Prisma Access (Managed by Strata Cloud Manager)
, or anytime
afterward.- —Strata Logging Service(Required)Prisma Accesslogs are stored inStrata Logging Service, and soPrisma Accessrequires you to also have aStrata Logging Servicelicense. It’s a good idea to activateStrata Logging Servicebefore you begin activatingPrisma Access. If you try to activatePrisma Accesswithout first activatingStrata Logging Service,Prisma Accesswill guide you to activateStrata Logging Servicebefore allowing you to continuePrisma Accessactivation. YourStrata Logging Serviceinstance andPrisma Accessinstance must be deployed in the same region.
- Cloud Identity Engine (Directory Sync)—Cloud Identity Engine givesPrisma Accessread-only access to your Active Directory information, so that you can easily set up and manage security and decryption policies for users and groups. Cloud Identity Engine is free and does not require a license to get started.
- SaaS Security API—Integrate SaaS Security API withPrisma Accessfor Clientless VPN and authentication support.
- Remote Browser Isolation (RBI)—Integrate RBI withPrisma Accessto provide a browsing environment that isolates all malware, including zero-day attacks that result from browsing and web activity, away from your end users and your network.
Prisma Access Add-On Licenses
Prisma Access
Add-On LicensesLearn about the add-on licenses that are provided by
Prisma Access
.You can add the following capabilities to use with
Prisma Access
as an add-on
license: